kkupdate.exe

快看影视

FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd

Publisher:
kuaikan studio  (signed by FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd)

Product:
快看影视

Description:
快看影视主程序

Version:
1.0.38.0323

MD5:
89cefb6eccc7d5755ca706f28a7d417d

SHA-1:
51b4bdfdb12a079ee050a4459f0df36c5fa72f51

SHA-256:
708b4b201080473d396240c760ed72fa9fd77a539cfd75e08b3793557f297fe9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/5/2024 2:37:43 PM UTC  (today)

File size:
232.2 KB (237,784 bytes)

Product version:
1.0.38.0323

Copyright:
Copyright (C) 2015 kuaikan studio

Original file name:
KKShowedFilms.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\kkshowedfilms\kkupdate.exe

Digital Signature
Authority:
WoSign CA Limited

Valid from:
10/26/2015 11:51:09 PM

Valid to:
10/26/2016 11:51:09 PM

Subject:
CN="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", O="FENGSHANG YUNQI Culture Media (Beijing) Co., Ltd", L=Beijing, S=Beijing, C=CN

Issuer:
CN=WoSign Class 3 Code Signing CA G2, O=WoSign CA Limited, C=CN

Serial number:
5BA22DD56638592FA5283CAFD23A41D9

File PE Metadata
Compilation timestamp:
3/22/2016 10:35:35 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
3072:XCqw88PpM8XwbLCRtPGjmKiphyQ7HBPtkpEdAzAg0FuUg2N9/n3pFKjO+LVWRd:yqAPpMnCNH75GedcAOXOb+Ls

Entry address:
0x13967

Entry point:
E8, C1, 72, 00, 00, E9, 7F, FE, FF, FF, 3B, 0D, 20, 10, 43, 00, 75, 02, F3, C3, E9, 54, 78, 00, 00, 58, 59, 87, 04, 24, FF, E0, CC, CC, CC, CC, CC, CC, CC, CC, CC, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 0F, 03, C1, 1B, C9, 0B, C1, 59, E9, 1A, 4E, 00, 00, 51, 8D, 4C, 24, 08, 2B, C8, 83, E1, 07, 03, C1, 1B, C9, 0B, C1, 59, E9, 04, 4E, 00, 00, CC, CC, CC, CC, 55, 8B, EC, 83, EC, 18, 53, 8B, 5D, 0C, 56, 57, C6, 45, FF, 00, 8B, 7B, 08, 8D, 73, 10, 33, 3D, 20, 10, 43, 00, C7, 45, F4, 01, 00, 00, 00, 8B, 07, 83, F8...
 
[+]

Entropy:
6.8617

Code size:
138 KB (141,312 bytes)

Scan kkupdate.exe - Powered by Reason Core Security